How to remove Window.exe
Window.exe
The module Window.exe has been detected as Trojan.CoinMiner
File Details
| Product Name: | Windows Defender |
| Company Name: | www.Microsoft.com |
| MD5: | 521e1c4b1915691c49d57000b73e6117 |
| Size: | 6 MB |
| First Published: | 2020-01-21 04:35:52 (5 years ago) |
| Latest Published: | 2021-10-09 20:39:35 (4 years ago) |
| Status: | Trojan.CoinMiner (on last analysis) | |
| Analysis Date: | 2021-10-09 20:39:35 (4 years ago) |
Common Places:
| %windir% |
| %windir% |
| %windir% |
| %windir% |
| %windir% |
| %windir% |
| %windir% |
| %windir% |
| %windir% |
| %windir% |
Geography:
| 94.1% | ||
| 5.9% |
OS Version:
| Windows 10 | 59.5% | |
| Windows 7 | 29.7% | |
| Windows 8.1 | 8.1% | |
| Windows Server 2012 R2 | 2.7% |
Analysis
| Subsystem: | Windows CUI |
| PE Type: | pe |
| OS Bitness: | 64 |
| Image Base: | 0x0000000000400000 |
| Entry Address: | 0x000014a0 |
PE Sections:
| Name | Size of data | MD5 |
| .text | 4952064 | 35fb065c4232d673282f21892022a340 |
| .data | 286720 | 1a152f5feda3a40c2e8e760509d0f244 |
| .rdata | 747520 | fa5b3cd85363050d8c89e28b39327de3 |
| .pdata | 172032 | e1306cf2af0f3a6f448b1039213c62bb |
| .xdata | 204800 | 448ba62842c185c4d916e69515ff7bf5 |
| .bss | 0 | 00000000000000000000000000000000 |
| .idata | 17408 | 255e457336acb894dc031726287fdd12 |
| .CRT | 512 | f76a237ae5f9db81178bd8d4e09d9dcf |
| .tls | 512 | bf619eac0cdf3f68d496ea9344137e8b |
| .rsrc | 79872 | 3a37bb2faf2431f7126d64872c57f86a |
More information:
Download GridinSoft
Anti-Malware - Removal tool for Window.exe